APP: Remote Desktop Services Chopper Header Overflow Remote Code Execution

This signature detects attempts to exploit a known vulnerability against implementation of RDP. A successful attack can lead to arbitrary code execution.

Extended Description

A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests. This vulnerability is pre-authentication and requires no user interaction. An attacker who successfully exploited this vulnerability could execute arbitrary code on the target system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. To exploit this vulnerability, an attacker would need to send a specially crafted request to the target systems Remote Desktop Service via RDP. The update addresses the vulnerability by correcting how Remote Desktop Services handles connection requests.

Affected Products

Microsoft windows_server_2016

References

CVE: CVE-2019-1182

Short Name
APP:REMOTE:RDP-CHOPPER-IO
Severity
Major
Recommended
False
Recommended Action
None
Category
APP
Keywords
CVE-2019-1181 CVE-2019-1182 Chopper Code Desktop Execution Header Overflow Remote Services
Release Date
08/20/2019
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3709
Port
UDP/3389
False Positive
Rarely
Vendors

Microsoft

CVSS Score

10.0

Found a potential security threat?